Home/Threat Actor/MirrorFace
Threat Actor

MirrorFace

mirrorface · china · active since 2019

MirrorFace (Earth Kasha / G1067) is a China-aligned cyber-espionage cluster active since 2019 and formally attributed to "MirrorFace, a cyber-attack group based in China" by joint Japanese government NPA + NISC public statement (January 2025), one of the most significant Japanese government cyber-attribution actions on public record, responsible for sustained operations against Japanese government, defense, defense industrial base, semiconductor, aerospace, manufacturing, academic, and political targets including the seminal Operation LiberalFace pre-election spear-phishing campaign against Japanese politicians ahead of the July 2022 House of Councillors election, defined operationally by the signature LODEINFO + ANEL + NOOPDOOR + HiddenFace + MirrorStealer + LockedDown toolkit (with LODEINFO and ANEL shared with APT10 / Stone Panda operations and one of the strongest signals of cluster-lineage adjacency to MSS Tianjin Bureau operations) and by sustained pre-electoral and post- electoral targeting of Japanese political processes.

china confidence: high 16 aliases MITRE ATT&CK G1054 ↗

Profile

MirrorFace (also tracked as Earth Kasha by Trend Micro, and operationally adjacent to APT10 / Stone Panda in some vendor assessments) is a China-aligned cyber-espionage cluster active since at least 2019 and formally attributed to "MirrorFace, a cyber-attack group based in China" by joint Japanese government statement from the National Police Agency (NPA) and National Center of Incident Readiness and Strategy for Cybersecurity (NISC) in early January 2025. The formal Japanese government attribution is one of a small handful of formal state attributions of MirrorFace-class clusters.

Japan has rarely issued comparable public cyber-attribution statements, making the MirrorFace attribution one of the most significant Japanese government cyber-attribution actions on public record. The attribution is at the "China-based cyber-attack group" level rather than at a specific MSS-bureau or PLA-unit level.

no Japanese or US government indictment of individual operators or contractor organizations has been published. Targeting focus is overwhelmingly directed at Japan, government, foreign affairs, defense, defense industrial base, semiconductors, aerospace, manufacturing, heavy industry, academic and research, and (a defining cluster characteristic) Japanese political organizations and politicians including pre-electoral and post- electoral targeting patterns. ESET's January 2023 "Operation LiberalFace" disclosure of a 2022 spear-phishing campaign against Japanese politicians in the run-up to the July 2022 House of Councillors election is the seminal public documentation of the cluster's political-process targeting and was a contributing element of the Japanese government's subsequent January 2025 attribution decision. Operationally MirrorFace's signature toolkit centers on LODEINFO, a .NET-based Windows implant first publicly disclosed by Kaspersky GReAT in March 2020 and undergoing continuous incremental evolution across subsequent years. LODEINFO provides command execution, file collection, screenshot capture, keylogging, and exfiltration capability against Japanese targets. Beyond LODEINFO the cluster operates ANEL (an older backdoor previously associated with APT10 / Stone Panda operations, shared between APT10 and MirrorFace and one of the strongest signals of cluster-lineage adjacency), NOOPDOOR (a previously-undocumented stealth backdoor analyzed by JPCERT/CC in February 2024), HiddenFace (a stealth Windows backdoor), MirrorStealer (a browser-credential and password-store theft tool), and LockedDown (a further implant disclosed in 2024). Cobalt Strike Beacon supplements the bespoke toolkit for hands-on-keyboard operations. Initial access patterns are predominantly spear-phishing with weaponized Office documents and ISO/archive attachments containing decoy documents and staged executable loaders, with selective exploitation of public-facing vulnerabilities (Exchange ProxyLogon, Fortinet, Array Networks, Ivanti, and others). The cluster does not appear to operate sustained zero-day-development capability and instead relies on rapid weaponization of disclosed n-day vulnerabilities alongside social-engineering tradecraft. The MirrorFace ↔ APT10 cluster-lineage question is one of the most analytically interesting elements of the cluster's profile. MirrorFace shares the LODEINFO and ANEL implant families with operations attributed to APT10 / Stone Panda (MSS Tianjin Bureau, already covered as apt10_stonepanda.yaml), and some vendor assessments treat MirrorFace as either an APT10 sub-cluster or an operational evolution of APT10 personnel. Trend Micro, JPCERT/CC, and ESET have maintained MirrorFace / Earth Kasha as a distinct cluster under separate naming, citing distinct operational signatures alongside the shared tooling. The lineage question remains analytically open.

the cluster could represent (a) APT10 personnel reassigned to a refocused operational mission against Japanese targets, (b) a separate MSS-aligned contractor operation that has acquired APT10 tooling, or (c) a cluster that has independently developed parallel tooling. The Japanese government's January 2025 attribution did not address the lineage question. A handful of operational notes: First, MirrorFace is operationally distinct from Tick / Bronze Butler (already covered as tick_bronze_butler.yaml) and from BlackTech / Earth Hundun (already covered as blacktech.yaml), despite all three clusters operating against Japanese targets. Tick has a distinctive Ichitaro 0day signature and Daserf/Datper/ T-SMB SCAN toolkit.

BlackTech operates Plead/TSCookie/Flagpro/ BendyBear and the Cisco router firmware implant tradecraft; MirrorFace operates LODEINFO/ANEL/NOOPDOOR/HiddenFace/MirrorStealer. The three clusters share Japan-targeting victimology but are clearly distinguishable on toolkit, tradecraft, and operational signature. Second, the cluster's late-2024 Trend Micro reporting (December 2024 "The Evolution of Earth Kasha, Targeting New Regions") documented geographic expansion beyond Japan into selected European and broader Asian targets, consistent with continued operational tempo and incremental expansion. The cluster remains predominantly Japan-focused but is no longer exclusively so. Third, attribution to a specific MSS bureau or contractor organization, though widely speculated within the APT10-lineage framing, has not been formally established. Treat the MSS- tasking framing as suspected at the bureau level even though the "China-based" framing is high-confidence by formal Japanese government attribution.

Aliases

16
mirrorfacemirror facemirror_faceearth kashaearth_kashaearthkashaoperation liberalfaceoperation_liberalfaceoperation_mirrorfaceapt10 sub_clusterapt10_sub_clusterlodeinfo clusterlodeinfo_clusterg1067atk 296atk296

Notable Campaigns

8
2025Japanese NPA + NISC Formal Public Attribution (January 2025)
2024-2025Continued Japanese Political and Pre-Election Targeting (2024-2025)
2024JPCERT/CC: NOOPDOOR Backdoor Analysis (February 2024)
2024LockedDown Implant Disclosure (2024)
2023-2024HiddenFace and MirrorStealer Tooling Expansion (2023-2024)
2023ESET: Operation LiberalFace, MirrorFace Targets Japanese Political Entities (January 2023)
2023Trend Micro: Earth Kasha, Threat Actor Continues Evolving (June 2023)
2020Kaspersky GReAT: LODEINFO Initial Disclosure (March 2020)

Attribution & Reporting

Attributed by
Japanese National Police Agency (NPA)Japanese National Center of Incident Readiness and Strategy for Cybersecurity (NISC)JPCERT/CCJapanese Ministry of Foreign Affairs (MOFA)Kaspersky GReATTrend MicroESETMacnica Networks (Japan)LAC Co. Ltd. (Japan)NTT SecurityCisco TalosSentinelOneMandiantMicrosoftRecorded Future Insikt GroupCluster25CyfirmaPWC
Key reporting
reportKaspersky GReAT: LODEINFO, Evolution of APT Techniques (March 2020), seminal toolkit disclosure
reportKaspersky GReAT: APT Trends Report Q2 2022, MirrorFace LODEINFO Continued Evolution
reportESET: Operation LiberalFace, MirrorFace Targets Japanese Political Entities (January 2023)
reportTrend Micro: Earth Kasha, Threat Actor Continues Evolving (June 2023)
reportTrend Micro: The Evolution of Earth Kasha, Targeting New Regions (December 2024)
reportMacnica Networks: MPression CSS Annual Report, Earth Kasha / MirrorFace Section (2023, Japanese-language)
reportJPCERT/CC: NOOPDOOR Backdoor Analysis Advisory (February 2024)
reportJPCERT/CC: MirrorFace Activity Alerts (multiple, 2023-2024)
reportLAC Co. Ltd.: APT Tracking, MirrorFace Section (Japanese-language, multiple years)
reportSekoia: MirrorFace LODEINFO Japan Targeting Tracking (2023-2024)
reportJapanese NPA + NISC Formal Joint Statement: MirrorFace Attribution to China-Based Cyber-Attack Group (January 8, 2025)
reportMalpedia Actor Profile: MirrorFace

Operational

State sponsor

China, formally attributed to "MirrorFace, a cyber-attack group based in China" by joint Japanese government statement from the National Police Agency (NPA) and National Center of Incident Readiness and Strategy for Cybersecurity (NISC) in early January 2025. The Japanese government attribution explicitly documented MirrorFace's sustained espionage operations against Japanese government, defense, defense industrial base, semiconductor, aerospace, manufacturing, academic, and political-organization targets since approximately 2019. The formal attribution is at the "China-based cyber-attack group" level rather than at a specific MSS-bureau or PLA-unit level.

no Japanese or US government indictment of individual operators or contractor organizations has been published. Vendor research consensus across Kaspersky GReAT, Trend Micro, ESET, JPCERT/CC, Macnica Networks, and others has consistently characterized MirrorFace as China-aligned and operationally adjacent to APT10 / Stone Panda (separately covered as apt10_stonepanda.yaml), sharing the LODEINFO and ANEL implant families with APT10, though operationally distinct in current vendor tracking. Some assessments treat MirrorFace as an APT10 sub-cluster or operational evolution.

Trend Micro and JPCERT have maintained it as a distinct cluster under the Earth Kasha and MirrorFace names respectively.

Motivations
espionage, intelligence_gathering, economic_espionage, intellectual_property_theft, geopolitical_collection, political_intelligence, defense_industrial_collection, semiconductor_industry_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)29/60 · 48%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

3 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSHTAMSI INSTALLER ABUSE
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin